Your Team Is Already Using AI. You Just Haven't Written Any Rules.

MIT called it the shadow AI economy: employees using consumer tools on company data without approval, because the work is easier that way and nobody told them not to. Governance is not a compliance exercise — it is the difference between AI being an asset and being a disclosure event.

The Risk Started Before the Strategy Did

Most governance conversations start with a hypothetical: what if we deploy AI and something goes wrong. That framing is already out of date. Your team adopted AI months ago, individually, using whatever was free and convenient.

The exposure is not theoretical. Client information pasted into a consumer chatbot to summarise a call. A contract uploaded to a free tool to check a clause. Candidate CVs run through a model to rank them. Each is a person doing their job faster, and each is data leaving your control under terms nobody has read.

Banning it does not work — it moves the behaviour further out of sight. What works is naming approved tools, drawing clear lines about data, and making the compliant path the easy one.

What we typically find

  • Client or patient data pasted into consumer AI tools to save time
  • Personal accounts used for work, so nothing is logged or recoverable
  • Contracts and financials uploaded to free tools with training rights in the terms
  • Model output used in client deliverables with nobody verifying the claims
  • No answer ready for the client asking whether their data touched an AI system
  • Nobody accountable when an automated decision turns out to be wrong

Six Things Governance Has to Answer

Short, specific, and written so an employee can follow them without asking a lawyer.

Which tools are approved

A named list, with the reason each is on it and what it may be used for. An approved option that is genuinely good is the most effective control you have — people route around rules that make their work harder.

What data may go in

Plain-language classification: what is fine, what needs a named approval, and what never leaves your systems. Most breaches we see are not defiance — they are people who had no idea where the line was.

Where a human must decide

Hiring, credit, pricing, medical, legal and disciplinary decisions need a named human owner regardless of how confident a model is. Written down before an automation is built, not after something goes wrong.

How vendors get reviewed

Where data is processed and stored, whether it trains their models, what the retention and deletion terms are, and what happens if they are acquired. A short checklist applied before purchase, not after renewal.

What gets logged

Enough record of automated decisions to reconstruct what happened and why. If you cannot answer “why did the system do that?” six months later, you cannot defend it to a client or a regulator.

What you tell customers

A clear position on how AI is used in your service, ready before a client asks in a procurement questionnaire. Increasingly this shows up in contracts, and having an answer already is becoming a competitive advantage.

Governance FAQs

What leadership teams ask once they realise this is already happening.

It is if you write it like a legal document and email it once. The version that works is two pages, names specific approved tools, gives concrete examples of allowed and prohibited use, and is introduced by explaining the reasoning rather than issuing rules.

The single biggest factor in compliance is whether the approved path is good. If the sanctioned tool is worse than what people are already using, the policy loses and you have simply made the behaviour invisible.

Your clients increasingly are, and their obligations flow to you through contracts. AI questions are appearing in standard procurement questionnaires, and a vague answer is now a reason to lose a deal.

There is also plain commercial exposure that has nothing to do with regulation — a confidentiality breach, a client discovering their data went into a third-party tool, or an automated decision you cannot explain.

If you operate in or sell into the EU, obligations depend on how your systems are classified, and the higher-risk categories carry real requirements. We will flag where you plausibly fall and what that implies.

We are not lawyers and we will not pretend to be. What we do is get you organised — an inventory of systems, documented decisions, and logging — so that when you take legal advice you are not starting from nothing. That preparation is most of the cost either way.

It can, and over-governing is a real failure mode — a heavyweight review board for a tool that drafts internal meeting notes will simply be bypassed.

The framework should be proportionate: light-touch for low-risk internal use, genuinely strict where decisions affect people's money, employment, health or legal position. Applying the same weight to both is how you get a policy nobody follows.

In most mid-sized companies it lands on operations, legal, or whoever raised the question — which is to say, nobody with the time. That is a large part of why the fractional role exists.

The goal is to hand it over. A framework somebody internal can run, with a named owner and a review cadence, beats a consultant permanently holding the only copy.

Find Out What's Already Happening

The readiness audit includes a shadow-AI review: what your team is actually using, on what data, under whose terms.